Rabbit R1s break after elevenlabs key revoked
twitter.com
twitter.com
Rabbit data breach (48 points, 2 hours ago, 11 comments) https://news.ycombinator.com/item?id=40792684
Rabbit R1: a fun, funky, unfinished AI gadget (40 points, 2 months ago, 69 comments) https://news.ycombinator.com/item?id=40145078
Rabbit R1 source code (353 points, 2 months ago, 189 comments) https://news.ycombinator.com/item?id=40135250
The Rabbit r1 is a ChatGPT based personal assistant device developed by tech startup Rabbit Inc,
https://en.m.wikipedia.org/wiki/Rabbit_r1
So not an adult toy (Rule 34 excepting)
https://rabbitu.de/articles/security-disclosure-1
tl;dr they had hardcoded their Elevenlabs admin keys into their client, which allowed anyone to access the entire history of TTS responses for every Rabbit R1 user
[0] https://gist.github.com/DavidBuchanan314/aafce6ba7fc49b19206...
oof
I would rate this as a "well, anyway...".
A lot of people are going to get scammed... again.
It's clear that they had absolutely no plan to deal with a compromised key. When approached, they probably have been trying to figure out the issue, are simply stuck in an unfixable state because they keys can't be rotated reliably.
Now that the issue is publicly known, they can't run their devices safely anymore.
I am willing to bet that you don't need their "codebase" as the Rabbitude hackers used, I bet these keys are hardcoded into the devices themselves, and that the key could probably be known within an hour or so and used to wreak havok.
So they opted to brick every R1, likely requiring a recovery on a PC using USB, and they need to work out their API key issue before they can ship anything, because there's a chance that any update would get compromised immediately too.
I hope every aspect of this grift is studied thoroughly so that investors understand not to throw money at people this unserious anymore.